If you jump down this rabbithole, you’re redirected to hxxp://www.eitool[.]com/SanJose/ help/userguide_files/adobe- cooperation-secure/index.php
This site is simply asking you to sign in with your
email and password, typical credential harvesting scam. There’s a fair
bit of javascript involved, and may be some landing page style nonsense
going on, but from my analysis box I don’t
see anything, could just be the harvest. I may try and dig into that more later.
Anyways, if you DO sign in, things get a little
more interesting. I threw in the throwaway credentials I have set up
exactly for instances like this, and it had me download a .doc file.
Interesting, I had expected to be redirected to a
public junk pdf.
Hmmm, does this doc contain macros? Why yes… yes it
does. Though it looks like they didn’t really configure it? There’s a
CitiBank logo at the top, and below that it says “Put here some text to
be more trustworthy!” Hahahaha, that’s pretty
hilarious. The rest of the English is pretty special too.
No comments:
Post a Comment